, , .
( - ):
:
begin
ShowMessage('! AVZ .'+#13#10+' .');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\WINDOWS\system32\machineupdate32.exe','');
QuarantineFile('C:\WINDOWS\system32\srvhls.exe','');
QuarantineFile('C:\WINDOWS\system32\uqfjwue.dll','');
QuarantineFile('C:\WINDOWS\system32\7A.tmp','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\elro.exe','');
DeleteFile('C:\WINDOWS\system32\7A.tmp');
DeleteFile('C:\Documents and Settings\Admin\Application Data\elro.exe');
DeleteFile('C:\WINDOWS\system32\uqfjwue.dll');
DeleteFile('C:\WINDOWS\system32\srvhls.exe');
DeleteFile('C:\WINDOWS\system32\machineupdate32.exe');
DeleteFileMask('C:\Documents and Settings\Admin\Application Data\WxAVLTzeDNU2ubx', '*.*', true);
DeleteDirectory('C:\Documents and Settings\Admin\Application Data\WxAVLTzeDNU2ubx');
DeleteFileMask('C:\Documents and Settings\Admin\Application Data\hyFGUTXVnxhwsSj', '*.*', true);
DeleteDirectory('C:\Documents and Settings\Admin\Application Data\hyFGUTXVnxhwsSj');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','Windows Debugger 32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
ExecuteWizard('SCU',2,3,true);
RebootWindows(true);
end.
, :
-
:
begin
CreateQurantineArchive(GetAVZDirectory+'quarantine.zip');
end.
AVZ : quarantine <at> safezone.cc ( <at> @) () . : virus .
HJT:
:
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,userinit.exe
O4 - HKCU\..\Policies\Explorer\Run: [Windows Debugger 32] C:\WINDOWS\system32\machineupdate32.exe
O20 - AppInit_DLLs: C:\WINDOWS\system32\uqfjwue.dll]
AVZ RSIT
Malwarebytes' Anti-Malware , , , " Perform Full Scan" (" "), " Scan" (" "), - Ok - Show Results (" ") - .
MBAM , . MBAM.
|